[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMyA4KsaxeTdwl_vilmdaaFvTmgff6uwlYjfun581_rA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"d31f3397-b51e-4059-9979-01ac33aa3fab","iranian-apt-nimbus-manticore-deploys-new-backdoor-and-ssh-tunneling-tools","4fbacd45-91cc-475c-a2a0-d1061749e147","Iranian APT Nimbus Manticore Deploys New Backdoor and SSH Tunneling Tools","Nimbus Manticore, an IRGC-affiliated Iranian state-sponsored group, has expanded its malware arsenal with a C++ backdoor resembling TWOSTROKE and a custom SSH tunneling utility, indicating deliberate capability development targeting organizations across the Middle East and Europe. The use of SSH tunneling is particularly concerning because it allows attackers to blend malicious traffic into legitimate encrypted channels, making detection significantly harder. This evolution of tooling signals a maturing threat actor with resources and intent to maintain persistent, covert access to compromised environments. Organizations that lack deep packet inspection, anomaly-based detection, and east-west traffic monitoring are especially vulnerable to this class of threat.","**Immediate actions:**\n- Audit and restrict all outbound SSH connections to explicitly authorized endpoints only.\n- Deploy behavioral detection rules in your SIEM to flag anomalous SSH tunnel establishment or unexpected C2 beaconing patterns.\n- Conduct threat-hunting exercises specifically looking for TWOSTROKE-like backdoor indicators of compromise (IOCs) on high-value systems.\n\n**Long-term improvements:**\n- Implement strict network segmentation to limit lateral movement opportunities if a backdoor achieves initial access.\n- Enforce application allowlisting on servers and endpoints to prevent unauthorized binaries (e.g., custom SSH utilities) from executing.\n- Maintain a continuously updated asset inventory and enforce baseline configuration standards to detect unauthorized software installations.\n\n**Detection measures:**\n- Enable full logging of process creation, network connections, and authentication events and forward them to a centralized SIEM with retention policies meeting regulatory minimums.\n- Subscribe to threat intelligence feeds covering Iranian APT activity (e.g., CISA advisories, MITRE ATT&CK G-group updates) to receive timely IOC updates.\n- Conduct regular purple team exercises simulating SSH tunneling and backdoor persistence techniques to validate detection coverage.",[12,13,14,15,16,17,18,19,20,21,22],"MITRE ATT&CK T1572 (Protocol Tunneling)","MITRE ATT&CK T1059 (Command and Scripting Interpreter)","MITRE ATT&CK T1071 (Application Layer Protocol)","CIS Control 4 (Secure Configuration of Enterprise Assets)","CIS Control 8 (Audit Log Management)","CIS Control 13 (Network Monitoring and Defense)","NIST SP 800-53 SI-3 (Malicious Code Protection)","NIST SP 800-53 AC-17 (Remote Access)","NIST SP 800-53 SC-7 (Boundary Protection)","NIST CSF DE.AE-1 (Network Anomaly Detection)","CISA Advisory AA24 Iranian IRGC Cyber Activity","published","2026-08-26T18:21:18.53023+00:00","2026-08-26T18:21:18.24+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fnimbus-manticore-expands-toolset-with.html","nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler-58d51b","Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]